Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited

Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited

Posted on September 6, 2026 By CWS

Online retailers using Magento Open Source and Adobe Commerce face an urgent threat from a newly discovered vulnerability. The zero-day exploit, identified by Dutch security firm Sansec as ‘StyleSmuggler’, is being leveraged by attackers to gain full control of e-commerce sites, with no official patch currently available.

Details of the StyleSmuggler Exploit

Sansec revealed the vulnerability on September 5, 2026, noting that it enables remote code execution without requiring authentication. The firm reported that attacks commenced the day before the disclosure. This exploit affects all current versions of Magento and Adobe Commerce, including the latest 2.4.9 release.

Alarmingly, even stores with up-to-date security patches are susceptible. Sansec confirmed this by reproducing the attack on installations of Magento Open Source 2.4.7, 2.4.8, and 2.4.9, showing that the flaw is not linked to outdated versions.

How the Attack Unfolds

The StyleSmuggler exploit unfolds in two stages, exploiting Magento’s template rendering and email systems. Initially, attackers insert malicious PHP code into files created during normal operations via a manipulated GraphQL request. This bypasses existing input sanitization measures.

In the second stage, the execution is triggered when Magento sends a standard ‘Payment Transaction Failed Reminder’ email. The malicious code is executed internally during this process, without any need for the email to be opened.

Defensive Measures and Recommendations

Detection is challenging as the malware disguises itself as a Linux kernel process, evading standard checks. Disrex Group, which conducted an independent analysis, found that the malware interacts with the store’s Redis instance, remaining hidden from network monitors.

Sansec suggests disabling GraphQL for those not using headless storefronts. Meanwhile, unofficial patches have been released by Disrex, ProxiBlue, and Graycore, though these are interim measures rather than permanent fixes. Server-level defenses, such as disabling PHP’s proc_open function, have also proven effective.

As store owners await Adobe’s next security release on September 8, they must rely on these temporary solutions to safeguard their platforms.

Stay informed and protect your online store from potential threats by implementing recommended security measures immediately.

Cyber Security News Tags:Adobe Commerce, Cybersecurity, Disrex, GraphQL, Magento, Malware, online stores, PHP code, RCE, Redis, Sansec, security patches, store protection, Vulnerability, zero-day

Post navigation

Previous Post: Magento and Adobe Commerce Vulnerability Exploited

Related Posts

Critical Vulnerability in etcd Allows Unauthorized API Access Critical Vulnerability in etcd Allows Unauthorized API Access Cyber Security News
Hive0156 Hackers Attacking Government and Military Organizations to Deploy Remcos RAT Hive0156 Hackers Attacking Government and Military Organizations to Deploy Remcos RAT Cyber Security News
New Phishing Kit Automates Generation of ClickFix Attack Bypassing Security Measures New Phishing Kit Automates Generation of ClickFix Attack Bypassing Security Measures Cyber Security News
Critical Trend Micro Apex One Management RCE Vulnerability Actively Exploited in the wild Critical Trend Micro Apex One Management RCE Vulnerability Actively Exploited in the wild Cyber Security News
Critical RCE Vulnerabilities Found in Cursor IDE Critical RCE Vulnerabilities Found in Cursor IDE Cyber Security News
SloppyLemming Espionage Targets South Asia with New Tools SloppyLemming Espionage Targets South Asia with New Tools Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act
  • Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act
  • Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark